# What is Operational Security (OPSEC)?

> Operational security (OPSEC), formally called operations security in many government sources, is a risk-management process for protecting critical information about activities, capabilities, intentions, and vulnerabilities.

- Canonical URL: https://yellowcube.eu/glossary/operational-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It examines what an adversary could learn from observable indicators — often individually unclassified or non-sensitive — and applies proportionate countermeasures to prevent those indicators from being combined into useful intelligence.

OPSEC is commonly organized as a recurring five-step process: identify critical information, analyze threats, analyze vulnerabilities and indicators, assess risk, and apply countermeasures. Effectiveness should then be evaluated as operations and adversary capabilities change.

### Key points

- **Critical information:** Determine the limited facts an adversary would need to frustrate an objective, predict timing, infer capability, select a target, or exploit a weakness.
- **Exposure and risk:** Examine capable adversaries, collection opportunities, public and internal indicators, vulnerabilities, likely inference, consequences, and the cost of protection.
- **Countermeasures:** Change timing or behavior, reduce unnecessary disclosure, control access, use approved concealment or deception, train personnel, and verify whether measures reduce risk.
- **Important limitation:** OPSEC cannot eliminate every observable indicator, and indiscriminate secrecy can obstruct safety, transparency, collaboration, or mission delivery. Countermeasures must be authorized, proportionate, lawful, and evaluated for unintended effects.

### Related terms

[Information security](<https://yellowcube.eu/glossary/information-security/>) · [Data classification](<https://yellowcube.eu/glossary/data-classification/>) · [Insider threat](<https://yellowcube.eu/glossary/insider-threat/>) · [Threat modeling](<https://yellowcube.eu/glossary/threat-modeling/>) · [Security operations (SecOps)](<https://yellowcube.eu/glossary/security-operations/>)

### Sources

[US Department of Defense Directive 5205.02E, DoD Operations Security (OPSEC) Program](https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/520502e.pdf) · [CISA, Guide to Operational Security for Election Officials](https://www.cisa.gov/sites/default/files/2024-07/Guide_to_Operational_Security_for_Election_Officials_07.01.24_508C.pdf) · [NIST SP 800-53 Rev. 5 Release 5.2.0](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

